Finextra Research
Sibos 2025
Sign in
Sign up
Sibos 2025
  • News
    • Latest news
    • Company updates
    • Long reads
  • TV
  • Research
  • Events
    • All
    • Conferences
    • Webinars
    • Popular
  • Community
    • Community latest
    • Latest expert opinions
    • Groups
    • Search members
  • Jobs
  • APIs
Sign in
Sign up
Sibos 2025
  • News
    • Back
    • News
    • Latest news
    • Company updates
    • Long reads
  • TV
  • Research
  • Events
    • Back
    • Events
    • All
    • Conferences
    • Webinars
    • Popular
  • Community
    • Back
    • Community
    • Community latest
    • Latest expert opinions
    • Groups
    • Search members
  • Jobs
  • APIs
  • payments
  • markets
  • retail
  • wholesale
  • wealth
  • regulation
  • crime
  • crypto
  • sustainable
  • startups
  • devops
  • identity
  • security
  • cloud
  • ai

Community

  • Your feed
  • Latest expert opinions
  • Groups

Join the Community

24,180
Expert opinions
40,757
Total members
368
New members (last 30 days)
213
New opinions (last 30 days)
29,301
Total comments
Join Sign in
Follow Unfollow

Bo Harald

Chairman/Founding member, board member
Trust Infra for Real Time Economy Prgrm & MyData,
Member since
04 Nov 2008
Location
Helsinki Region
Followers
24
Following
0
Opinions
582
Long reads
0
Followed by John Sims, Martha Boyle and 5 others you follow

Bio

Independent advisor and board professional

Experience

Chairman/Founding member, board member
Trust Infra for Real Time Economy Prgrm & MyData,
To Present
Show all experience

Latest opinions

Bo Harald

Fixing the original sin..

As we all know, fixing the original no-identity-sin of Internet – with verifiable identification and other credentials - is the starting point for “everything”. When organisational wallets (branded EUBW) are taken in use issuing and verifying all sorts of credentials (all the way to product passports) can be done without need for technical integra...

17 hours Transaction Banking

Bo Harald

How could EUDI and the First Person Project support each other

I had to ask Drummond Reed if ChatGPT got this right. He said: Bo, I must say, ChatGPT continues to amaze me at what it can figure out and then articulate. Yes, I believe everything it says is quite accurate. That's why my mission is to get the First Person Project the resources we need to succeed. Stay tuned! Best, =Drummond ChatGPT

30 October 2025 Innovation in Financial Services

Bo Harald

How does LPID and vLEI work together? Or are they competing?

With the EUBW work now in high gear there may not be enough attention to GLEIF. Some may think that they are competing. ChatGPT said: Excellent and timely question — and one that many in the eIDAS / Trust over IP / GLEIF / MyData / Findynet circles are quietly wrestling with right now. Let’s strip the jargon down and look at it

29 October 2025 Innovation in Financial Services

See all 582 opinions by Bo

Latest comments

Zero Trust in Europe

There isn’t a single, standalone protocol that everyone calls “Zero Trust Authorisation Protocol.” Zero Trust is a security architecture and mindset—“never trust, always verify”—rather than a formal RFC-defined wire protocol. What you’ll actually see in production are protocol stacks and policy engines built to enforce Zero Trust principles:

  • Authentication & Federation:

    • OIDC / OAuth 2.0 – Used for delegated auth with continuous verification.

    • SAML 2.0 – Older but still used in enterprises.

    • FIDO2/WebAuthn – Phishing-resistant, passwordless auth for Zero Trust endpoints.

  • Policy Decision/Enforcement:

    • XACML or OPA (Open Policy Agent) – Express fine-grained, attribute-based access control (ABAC).

    • SPIFFE/SPIRE – Secure workload identities in service meshes.

    • gRPC/Envoy + mTLS – For microservice-to-microservice trust with certificate rotation.

  • Zero Trust Frameworks/Specs:

    • NIST SP 800-207 – The de facto reference for Zero Trust architecture.

    • CNCF Zero Trust Working Groups – Define patterns for cloud-native stacks.

    • Google BeyondCorp – A reference implementation (not a protocol) showing continuous verification of user, device, and context.

So if you’re looking for one standardised “Zero Trust authorisation protocol,” it doesn’t exist. The industry achieves Zero Trust by composing existing protocols (OAuth 2.0 + OIDC + mTLS + ABAC/RBAC engines) under strict “verify every access, every time” policies. If you need a starting point:

  1. NIST SP 800-207 – for architecture principles.

  2. OAuth 2.0 + OIDC with continuous re-auth and device posture checks.

  3. OPA or XACML for dynamic, context-aware authorisation decisions.

  4. mTLS/SPIFFE for workload identities inside your network.

That’s the current state of play—Zero Trust is a design pattern, not a new protocol.

 
 

14 Sep 2025 17:28 Read comment

BankID credentials paving the way for EU Business Wallet

Valuable wider view: https://www.linkedin.com/posts/bo-harald-4768b51_from-ai-slop-to-signal-verifiable-provenance-activity-7362832443499773953-jdHY?utm_source=share&utm_medium=member_desktop&rcm=ACoAAABPj1oB9_D7YNYACmHvY9HioUqpuULqZCo

20 Aug 2025 05:58 Read comment

Two Paradigm Shifts: Trust Infrastructure and AI-Agentics

Google Notebook crystallized here: https://www.linkedin.com/posts/bo-harald-4768b51_google-notebook-in-the-know-activity-7355968433387192321-d_ix?utm_source=share&utm_medium=member_desktop&rcm=ACoAAABPj1oB9_D7YNYACmHvY9HioUqpuULqZCo

30 Jul 2025 18:37 Read comment

See all 320 comments by Bo

Bo writes about

  • artificial intelligence
  • security
  • payments
  • regulation & compliance
  • people
  • wealth management
  • retail banking
  • wholesale banking
  • sustainable
  • financial inclusion
  • identity
  • financial crime
  • predictions

Bo's opinion archive

  • 2025 (90)
  • 2024 (31)
  • 2023 (13)
  • 2022 (10)
  • 2020 (6)
  • 2019 (14)
  • 2018 (24)
  • 2017 (15)
  • 2016 (16)
  • 2015 (13)
  • 2014 (17)
  • 2013 (16)
  • 2012 (35)
  • 2011 (70)
  • 2010 (74)
  • 2009 (85)
  • 2008 (10)

Latest groups joined by Bo

  • Electronic invoicing

  • Whatever...

  • Transaction Banking

See all groups joined

Bo reads

  • Networked economy
  • Real Time Economy

Welcome to Finextra. We use cookies to help us to deliver our services. You may change your preferences at our Cookie Centre.

Please read our Privacy Policy.

Accept
Finextra

Finextra

  • About

Community

  • Rules
  • Contact the community team

News

  • Guidance
  • Contact the news desk

Sales

  • Media pack
  • Contact the sales team

Get involved

  • Finextra Live@
  • Webinars
  • Finextra TV
  • Research
  • Finextra.jobs
  • Finextra Pro

Events

  • Sustainable Finance Live
  • NextGen Nordics
  • EBAday
  • NextGen:AI

Members

Join the community News alerts

Follow

Download Finextra Pro

Download Finextra Pro from Apple App Store Download Finextra Pro from Google App Store

Download Finextra News

Download Finextra News from Apple App Store Download Finextra News from Google App Store

© Finextra Research 2025

Terms of usePrivacy PolicyCookie Centre